SV-214672r382783_rule
V-214672
SRG-NET-000062
JUSX-VN-000005
CAT I
10
The following example commands configure the IPsec (phase 2) proposals. The option may also be configured to use the aes-128-cbc, aes-192-cbc, or aes-256-cbc algorithms.
[edit]
set security ipsec proposal <IPSEC-PROPOSAL-NAME> encryption-algorithm aes-256-cbc
Verify all Internet Key Exchange (IKE) proposals are set to use the AES encryption algorithm.
[edit]
show security ipsec
View the value of the encryption algorithm for each defined proposal.
If the value of the encryption algorithm for any IPsec proposal is not set to use an AES algorithm, this is a finding.
V-214672
False
JUSX-VN-000005
Verify all Internet Key Exchange (IKE) proposals are set to use the AES encryption algorithm.
[edit]
show security ipsec
View the value of the encryption algorithm for each defined proposal.
If the value of the encryption algorithm for any IPsec proposal is not set to use an AES algorithm, this is a finding.
M
4009